Shop flooded with “weird orders”? It might be stolen card testing, not a hack
This happened to one of our clients. We designed and built their online shop, and we currently host it too. The client noticed a sudden surge of strange orders in the admin panel and contacted us straight away because it looked like a break-in.
It quickly turned out it wasn’t a website hack at all, but a clever fraud pattern where the store was used as a “testing tool” for payment cards.
This issue was new to us at the time, but it’s surprisingly common in e-commerce: card testing – automated testing of stolen card details on random online stores.
What this scam is about
Fraudsters buy batches of card data (for example from data leaks) and run a bot that makes lots of small payment attempts across different websites. The goal is to find out which cards are still active. If a payment goes through, that card becomes “validated” and more valuable. They can then use it for larger purchases elsewhere or sell it for more. Payment industry guidance describes these attacks as low-value, high-volume tests carried out at scale.
The key point: your store is often just the “test machine”. The bot doesn’t need to steal anything from your website. It simply uses your checkout to test cards.
What it looks like for the store owner
The most common warning signs are a sudden spike in failed orders, or lots of attempts with different cards in a short period of time. WooCommerce describes this as a typical symptom of card testing.
And it comes with real costs and stress:
- transaction fees from repeated authorisation attempts
- chargeback/dispute risk
- admin chaos and time wasted

Why it’s especially risky for dropshipping
If you run a shop and dispatch orders yourself, you’ll usually notice something is off and pause fulfilment.
With dropshipping (where a supplier or fulfilment partner ships orders for you), the risk is higher. If even some payments go through, the system may automatically send the order for fulfilment. Later, the payment is reversed, the goods are already shipped, and you’re left with the loss.
How we solved it for our client (step by step)
These attacks often force a “test, measure, improve” approach, because different protections can stop bots but sometimes also block genuine customers.
- First, we found a video explaining this exact issue and recommending a code-based block to prevent bots from going straight to basket/checkout to test cards quickly.
- It worked – but came with a side effect: it also blocked PayPal payments for this client. So bots were stopped, but legitimate customers were affected too.
- Next, we added a plugin to catch suspicious orders (flagging/holding them). This reduced fulfilment risk, but orders were still coming in – they were simply being flagged. That meant more manual work and the stress didn’t really go away.
In the end, we went with a simple, proven layer of protection: Google reCAPTCHA added directly in the basket/checkout stage.
That was the breakthrough. Bots stopped getting through, and normal payments worked again. reCAPTCHA is specifically recommended as a practice to reduce automated abuse like card testing and protect transaction flows.
What you can do before it happens to you
If you run an online store, treat this as a quick “common sense” checklist:
First, protect the most sensitive area: your checkout. CAPTCHA/reCAPTCHA at the payment stage is one of the simplest and most commonly recommended ways to stop card-testing bots.
Second, set “velocity” limits – blocks for too many attempts in a short time. In practice, that can mean rate limiting checkout endpoints or adding WAF protection. It’s a strong combo together with CAPTCHA.
In our case, velocity rules alone didn’t solve it because the automated purchases were spread over time and didn’t trigger the limit.
Third, monitor anomalies. If failed orders suddenly rise, you see hundreds of similar attempts, or “weird things” happen quickly – react immediately. WooCommerce documentation points to monitoring transactions as the first and simplest warning signal.
Why we’re sharing this
Because many people build online shops “as cheaply as possible”: DIY, random hosting, no technical support, “as long as it works”. And while it works, everything feels fine. But when an attack like this happens, the owner is often left alone – hosting support usually won’t help, and time is not on your side.
This isn’t about scaremongering. It’s just another reminder that in e-commerce, it’s not only design and products that matter – it’s also fast response and technical know-how. And having real humans behind your store who can step in quickly. 🙂
So if you’re thinking about an online shop for your business, think about having a proven team behind it… like us.
en
pl